Nukeviet is a content-management and e-government platform with a modestly sized but strategically positioned presence in the vulnerability landscape, particularly in Southeast Asian public administration deployments. Its vulnerabilities skew strongly toward critical-severity outcomes and concentrate in the core Nukeviet and e-Government products through recurrent application-layer weakness classes including cross-site request forgery, SQL injection, deserialization flaws, cross-site scripting, and code injection—a profile typical of PHP-based CMS platforms with complex input-handling and template-processing surfaces. Defenders managing public-sector or government-facing instances should prioritize security assessment and patch deployment for this vendor; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nukeviet over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21809CRITICAL SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.ph | Jul 30, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-21808CRITICAL SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php. | Jul 30, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-13155HIGH clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI. | Jun 23, 2020 | 8.8 | 28 | NO | NO |
CVE-2024-36528HIGH nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/e | Jun 10, 2024 | 8.8 | 26 | NO | NO |
CVE-2019-7725CRITICAL includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to elim | Dec 31, 2020 | 9.8 | 25 | NO | NO |
CVE-2019-7726CRITICAL modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and User-Agent). | Dec 31, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-13156MEDIUM modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI. | Jun 23, 2020 | 6.5 | 22 | NO | NO |
CVE-2020-22765MEDIUM Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module. | Jul 30, 2021 | 6.1 | 21 | NO | NO |
CVE-2025-8772MEDIUM A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file /admin/index.php?langu | Aug 9, 2025 | 4.3 | 18 | NO | NO |
CVE-2024-36531MEDIUM nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component. | Jun 10, 2024 | 5.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nukeviet.
Media articles that mention a CVE ID that affects a product developed by Nukeviet — matched by CVE ID, not by vendor name.